======================================
| [ 71.238002][ T520] br1: port 1(veth1) entered forwarding state
| [ 71.242090][ C2] ------------[ cut here ]------------
| [ 71.242460][ C2] UBSAN: invalid-load in ./include/linux/skbuff.h:4267:9
| [ 71.242834][ C2] load of value 107 is not a valid value for type '_Bool'
[ 71.243574][ C2] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
[ 71.244183][ C2] Call Trace:
[ 71.244357][ C2]
[ 71.244506][ C2] dump_stack_lvl (lib/dump_stack.c:107)
[ 71.244749][ C2] __ubsan_handle_load_invalid_value (lib/ubsan.c:218 lib/ubsan.c:419)
[ 71.245075][ C2] br_forward_finish.cold (./include/linux/spinlock.h:396 net/bridge/br.c:81) bridge
[ 71.245462][ C2] deliver_clone (net/bridge/br_forward.c:132) bridge
[ 71.245765][ C2] maybe_deliver (net/bridge/br_forward.c:191) bridge
[ 71.246081][ C2] br_flood (net/bridge/br_forward.c:236) bridge
[ 71.246375][ C2] br_dev_xmit (net/bridge/br_device.c:100) bridge
[ 71.246685][ C2] ? __pfx_br_dev_xmit (net/bridge/br_device.c:29) bridge
[ 71.247020][ C2] ? lock_acqui
DETECTED CRASH, lowering timeout
re.part.0+0xe5/0x330
[ 71.247289][ C2] ? __pfx_skb_network_protocol (net/core/dev.c:3341)
[ 71.247588][ C2] ? __pfx_qdisc_pkt_len_init (net/core/dev.c:3679)
[ 71.247872][ C2] ? __pfx_lock_acquire.part.0 (kernel/locking/lockdep.c:5719)
[ 71.248166][ C2] dev_hard_start_xmit (./include/linux/netdevice.h:4991 ./include/linux/netdevice.h:5005 net/core/dev.c:3530 net/core/dev.c:3546)
[ 71.248437][ C2] __dev_queue_xmit (./include/linux/netdevice.h:3369 net/core/dev.c:4338)
[ 71.248697][ C2] ? mark_held_locks (kernel/locking/lockdep.c:4274)
[ 71.248945][ C2] ? eth_header (net/ethernet/eth.c:100)
[ 71.249185][ C2] ? __pfx___dev_queue_xmit (net/core/dev.c:4246)
[ 71.249459][ C2] ? neigh_resolve_output (./include/linux/netdevice.h:3226 net/core/neighbour.c:1558 net/core/neighbour.c:1543)
[ 71.249748][ C2] ip_finish_output2 (./include/net/neighbour.h:542 net/ipv4/ip_output.c:235)
[ 71.250012][ C2] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228)
[ 71.250250][ C2] ? __pfx_ip_finish_output2 (net/ipv4/ip_output.c:199)
[ 71.250533][ C2] ? __ip_finish_output (./include/linux/skbuff.h:1627 ./include/linux/skbuff.h:4943 net/ipv4/ip_output.c:307 net/ipv4/ip_output.c:295)
[ 71.250807][ C2] ip_output (./include/linux/netfilter.h:303 net/ipv4/ip_output.c:433)
[ 71.251030][ C2] ? __pfx_ip_output (net/ipv4/ip_output.c:427)
[ 71.251281][ C2] ? igmpv3_send_cr (net/ipv4/igmp.c:721)
[ 71.251541][ C2] ? ip_local_out (net/ipv4/ip_output.c:128)
[ 71.251783][ C2] igmp_ifc_timer_expire (net/ipv4/igmp.c:815)
[ 71.252051][ C2] ? __pfx_igmp_ifc_timer_expire (net/ipv4/igmp.c:809)
[ 71.252350][ C2] call_timer_fn (kernel/time/timer.c:1700)
[ 71.252594][ C2] ? __pfx_call_timer_fn (kernel/time/timer.c:1677)
[ 71.252859][ C2] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228)
[ 71.253096][ C2] ? mark_held_locks (kernel/locking/lockdep.c:4274)
[ 71.253363][ C2] __run_timers.part.0 (kernel/time/timer.c:1752 kernel/time/timer.c:2038)
[ 71.253624][ C2] ? __pfx_igmp_ifc_timer_expire (net/ipv4/igmp.c:809)
[ 71.253929][ C2] ? __pfx___lock_release (kernel/locking/lockdep.c:5406)
[ 71.254196][ C2] ? __pfx___run_timers.part.0 (kernel/time/timer.c:2007)
[ 71.254484][ C2] ? clockevents_program_event (kernel/time/clockevents.c:326)
[ 71.254785][ C2] ? hlock_class (./arch/x86/include/asm/bitops.h:227 ./arch/x86/include/asm/bitops.h:239 ./include/asm-generic/bitops/instrumented-non-atomic.h:142 kernel/locking/lockdep.c:228)
[ 71.255019][ C2] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 3))
[ 71.255252][ C2] run_timer_softirq (kernel/time/timer.c:2012 kernel/time/timer.c:2053)
[ 71.255506][ C2] __do_softirq (kernel/softirq.c:553)
[ 71.255751][ C2] irq_exit_rcu (kernel/softirq.c:427 kernel/softirq.c:632 kernel/softirq.c:644)
[ 71.255975][ C2] sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1076 (discriminator 14))
[ 71.256262][ C2]
[ 71.256417][ C2]
[ 71.256571][ C2] asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:649)
[ 71.256880][ C2] RIP: 0010:_raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:152 kernel/locking/spinlock.c:194)
[ 71.257206][ C2] Code: 10 e8 41 79 a4 fd 48 89 ef e8 59 01 a5 fd 81 e3 00 02 00 00 75 1d 9c 58 f6 c4 02 75 29 48 85 db 74 01 fb 65 ff 0d 15 db b5 4f <74> 0e 5b 5d c3 cc cc cc cc e8 2f c0 c6 fd eb dc 0f 1f 44 00 00 5b
All code
========
0: 10 e8 adc %ch,%al
2: 41 79 a4 rex.B jns 0xffffffffffffffa9
5: fd std
6: 48 89 ef mov %rbp,%rdi
9: e8 59 01 a5 fd call 0xfffffffffda50167
e: 81 e3 00 02 00 00 and $0x200,%ebx
14: 75 1d jne 0x33
16: 9c pushf
17: 58 pop %rax
18: f6 c4 02 test $0x2,%ah
1b: 75 29 jne 0x46
1d: 48 85 db test %rbx,%rbx
20: 74 01 je 0x23
22: fb sti
23: 65 ff 0d 15 db b5 4f decl %gs:0x4fb5db15(%rip) # 0x4fb5db3f
2a:* 74 0e je 0x3a <-- trapping instruction
2c: 5b pop %rbx
2d: 5d pop %rbp
2e: c3 ret
2f: cc int3
30: cc int3
31: cc int3
32: cc int3
33: e8 2f c0 c6 fd call 0xfffffffffdc6c067
38: eb dc jmp 0x16
3a: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1)
3f: 5b pop %rbx
Code starting with the faulting instruction
===========================================
0: 74 0e je 0x10
2: 5b pop %rbx
3: 5d pop %rbp
4: c3 ret
5: cc int3
6: cc int3
7: cc int3
8: cc int3
9: e8 2f c0 c6 fd call 0xfffffffffdc6c03d
e: eb dc jmp 0xffffffffffffffec
10: 0f 1f 44 00 00 nopl 0x0(%rax,%rax,1)
15: 5b pop %rbx
[ 71.258168][ C2] RSP: 0000:ffffc90000f6f9d8 EFLAGS: 00000286
[ 71.258479][ C2] RAX: 0000000000000002 RBX: 0000000000000200 RCX: 1ffffffff674f8fd
[ 71.258877][ C2] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffffb069dbc1
[ 71.259274][ C2] RBP: ffff888001040a80 R08: 0000000000000001 R09: fffffbfff674cc7d
[ 71.259674][ C2] R10: ffffffffb3a663ef R11: 0000000000000040 R12: ffff8880071b2680
[ 71.260071][ C2] R13: 0000000000000000 R14: ffffc90000f6fa28 R15: ffff8880071b2680
[ 71.260483][ C2] ? _raw_spin_unlock_irqrestore (./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194)
[ 71.260788][ C2] qlist_free_all (mm/kasan/quarantine.c:171)
[ 71.261034][ C2] kasan_quarantine_reduce (./include/linux/srcu.h:285 mm/kasan/quarantine.c:284)
[ 71.261318][ C2] __kasan_slab_alloc (mm/kasan/common.c:324)
[ 71.261573][ C2] kmem_cache_alloc (./include/linux/kasan.h:201 mm/slub.c:3813 mm/slub.c:3860 mm/slub.c:3867)
[ 71.261832][ C2] __alloc_object (mm/kmemleak.c:466 mm/kmemleak.c:645)
[ 71.262077][ C2] __create_object (mm/kmemleak.c:750)
[ 71.262319][ C2] kmem_cache_alloc (./include/linux/kmemleak.h:42 mm/slub.c:3817 mm/slub.c:3860 mm/slub.c:3867)
[ 71.262579][ C2] __anon_vma_prepare (mm/rmap.c:94 mm/rmap.c:203)
[ 71.262841][ C2] wp_page_copy (mm/memory.c:3094 mm/memory.c:3133)
[ 71.263081][ C2] ? __pfx___lock_acquired (kernel/locking/lockdep.c:5959)
[ 71.263367][ C2] ? __pfx_wp_page_copy (mm/memory.c:3117)
[ 71.263624][ C2] ? __pfx_vm_normal_page (mm/memory.c:584)
[ 71.263893][ C2] ? rcu_read_unlock (./include/linux/rcupdate.h:308 (discriminator 9) ./include/linux/rcupdate.h:783 (discriminator 9))
[ 71.264143][ C2] ? do_wp_page (mm/memory.c:3525)
[ 71.264382][ C2] __handle_mm_fault (mm/memory.c:5285)
[ 71.264638][ C2] ? __pfx___handle_mm_fault (mm/memory.c:5196)
[ 71.264943][ C2] handle_mm_fault (mm/memory.c:5454)
[ 71.265192][ C2] ? __pfx_find_vma (mm/mmap.c:1883)
[ 71.265436][ C2] ? __pfx_handle_mm_fault (mm/memory.c:5420)
[ 71.265719][ C2] do_user_addr_fault (arch/x86/mm/fault.c:1417)
[ 71.265981][ C2] ? irqentry_enter_from_user_mode (./include/linux/entry-common.h:117 kernel/entry/common.c:219)
[ 71.266293][ C2] exc_page_fault (./arch/x86/include/asm/irqflags.h:26 ./arch/x86/include/asm/irqflags.h:67 ./arch/x86/include/asm/irqflags.h:127 arch/x86/mm/fault.c:1515 arch/x86/mm/fault.c:1563)
[ 71.266530][ C2] asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:570)
[ 71.266778][ C2] RIP: 0033:0x7febb6a2068c
[ 71.267008][ C2] Code: 1e fa 80 3d 95 59 01 00 00 75 2b 55 48 83 3d 6a 59 01 00 00 48 89 e5 74 0c 48 8d 3d 3e 54 01 00 e8 59 ff ff ff e8 64 ff ff ff 05 6d 59 01 00 01 5d c3 0f 1f 00 c3 0f 1f 80 00 00 00 00 f3 0f
All code
========
0: 1e (bad)
1: fa cli
2: 80 3d 95 59 01 00 00 cmpb $0x0,0x15995(%rip) # 0x1599e
9: 75 2b jne 0x36
b: 55 push %rbp
c: 48 83 3d 6a 59 01 00 cmpq $0x0,0x1596a(%rip) # 0x1597e
13: 00
14: 48 89 e5 mov %rsp,%rbp
17: 74 0c je 0x25
19: 48 8d 3d 3e 54 01 00 lea 0x1543e(%rip),%rdi # 0x1545e
20: e8 59 ff ff ff call 0xffffffffffffff7e
25: e8 64 ff ff ff call 0xffffffffffffff8e
2a:* c6 05 6d 59 01 00 01 movb $0x1,0x1596d(%rip) # 0x1599e <-- trapping instruction
31: 5d pop %rbp
32: c3 ret
33: 0f 1f 00 nopl (%rax)
36: c3 ret
37: 0f 1f 80 00 00 00 00 nopl 0x0(%rax)
3e: f3 repz
3f: 0f .byte 0xf
Code starting with the faulting instruction
===========================================
0: c6 05 6d 59 01 00 01 movb $0x1,0x1596d(%rip) # 0x15974
7: 5d pop %rbp
8: c3 ret
9: 0f 1f 00 nopl (%rax)
c: c3 ret
d: 0f 1f 80 00 00 00 00 nopl 0x0(%rax)
14: f3 repz
15: 0f .byte 0xf
[ 71.267971][ C2] RSP: 002b:00007ffd1bd95500 EFLAGS: 00010246
[ 71.268280][ C2] RAX: 00007febb6a36000 RBX: 00007febb6d74000 RCX: 0000000000000000
[ 71.268676][ C2] RDX: 0000000000000001 RSI: 0000000000000000 RDI: 00007febb6a36000
[ 71.269074][ C2] RBP: 00007ffd1bd95500 R08: 0000000000000000 R09: 0000000000000058
[ 71.269474][ C2] R10: 00007ffd1bd95400 R11: 00007ffd1bd95400 R12: 0000000000000000
Finger prints:
dump_stack_lvl:__ubsan_handle_load_invalid_value:deliver_clone:maybe_deliver